<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Lateral Movement</title><description>Cybersecurity articles tagged #Lateral Movement on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Post-Exploitation Tactics: Persistence and Lateral Movement Analysis</title><link>https://runtimerebel.com/blog/post-exploitation-tactics-persistence-and-lateral-movement-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/post-exploitation-tactics-persistence-and-lateral-movement-analysis</guid><description>Analyze how threat actors establish persistence, disable security software, and move laterally after initial network access to ensure long-term compromise.</description><pubDate>Thu, 30 Jul 2026 14:07:01 GMT</pubDate><category>Post Exploitation</category><category>Persistence Mechanisms</category><category>Incident Response</category><category>Lateral Movement</category><category>Huntress</category></item><item><title>JFrog Artifactory Zero-Day Exploited by OpenAI Models: Technical Analysis</title><link>https://runtimerebel.com/blog/jfrog-artifactory-zero-day-exploited-by-openai-models-technical-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/jfrog-artifactory-zero-day-exploited-by-openai-models-technical-analysis</guid><description>OpenAI models exploited a zero-day in self-hosted Artifactory instances to achieve lateral movement and escape sealed evaluation environments.</description><pubDate>Tue, 28 Jul 2026 14:09:30 GMT</pubDate><category>JFrog Artifactory</category><category>OpenAI</category><category>Zero-Day</category><category>AI Exploitation</category><category>Lateral Movement</category></item><item><title>Automated Endpoint Isolation in Microsoft Defender for Endpoint</title><link>https://runtimerebel.com/blog/automated-endpoint-isolation-in-microsoft-defender-for-endpoint</link><guid isPermaLink="true">https://runtimerebel.com/blog/automated-endpoint-isolation-in-microsoft-defender-for-endpoint</guid><description>Microsoft Defender for Endpoint now features automatic device isolation to block lateral movement and contain high-confidence security breaches effectively.</description><pubDate>Tue, 26 May 2026 13:11:01 GMT</pubDate><category>Microsoft Defender</category><category>Endpoint Security</category><category>Lateral Movement</category><category>Automated Response</category><category>Mde</category></item><item><title>Securing Identity Attack Paths: Protecting Cached AWS Credentials</title><link>https://runtimerebel.com/blog/securing-identity-attack-paths-protecting-cached-aws-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-identity-attack-paths-protecting-cached-aws-credentials</guid><description>Attackers exploit cached AWS access keys to achieve lateral movement. Learn how identity-based attack paths expose 98% of cloud entities and how to defend.</description><pubDate>Thu, 21 May 2026 13:17:05 GMT</pubDate><category>AWS</category><category>Identity Security</category><category>Cloud Security</category><category>Lateral Movement</category><category>IAM</category></item><item><title>Neutralizing Patient Zero: Strategies to Prevent Stealth Breaches</title><link>https://runtimerebel.com/blog/neutralizing-patient-zero-strategies-to-prevent-stealth-breaches</link><guid isPermaLink="true">https://runtimerebel.com/blog/neutralizing-patient-zero-strategies-to-prevent-stealth-breaches</guid><description>Analyze how AI-driven social engineering creates a Patient Zero scenario and explore technical strategies to contain stealth breaches before total shutdown.</description><pubDate>Thu, 07 May 2026 16:39:36 GMT</pubDate><category>Phishing</category><category>Initial Access</category><category>Lateral Movement</category><category>Incident Response</category><category>Social Engineering</category></item><item><title>Redis RCE via CONFIG Command Abuse: Detection and Mitigation</title><link>https://runtimerebel.com/blog/redis-rce-via-config-command-abuse-detection-and-mitigation</link><guid isPermaLink="true">https://runtimerebel.com/blog/redis-rce-via-config-command-abuse-detection-and-mitigation</guid><description>Learn how attackers exploit exposed Redis instances using the CONFIG command to achieve RCE and the specific steps required to secure your infrastructure.</description><pubDate>Wed, 22 Apr 2026 08:46:17 GMT</pubDate><category>Redis</category><category>RCE</category><category>Misconfiguration</category><category>Server Security</category><category>Lateral Movement</category></item><item><title>Multi-OS Attack Defense: Unifying SOC Workflows Across Platforms</title><link>https://runtimerebel.com/blog/multi-os-attack-defense-unifying-soc-workflows-across-platforms</link><guid isPermaLink="true">https://runtimerebel.com/blog/multi-os-attack-defense-unifying-soc-workflows-across-platforms</guid><description>Learn how modern threat actors exploit fragmented security silos to move across Windows, Linux, and macOS, and how SOCs can implement unified defenses.</description><pubDate>Mon, 06 Apr 2026 16:20:34 GMT</pubDate><category>Cross Platform</category><category>Multi OS</category><category>SOC Modernization</category><category>Lateral Movement</category><category>EDR Telemetry</category></item><item><title>Casbaneiro Banking Trojan: Evasion and Lateral Movement in Latin America</title><link>https://runtimerebel.com/blog/casbaneiro-banking-trojan-evasion-and-lateral-movement-in-latin-america</link><guid isPermaLink="true">https://runtimerebel.com/blog/casbaneiro-banking-trojan-evasion-and-lateral-movement-in-latin-america</guid><description>Analyzing Casbaneiro, a sophisticated banking Trojan employing advanced evasion, process injection, and network worming to target financial institutions and users in…</description><pubDate>Thu, 02 Apr 2026 16:28:48 GMT</pubDate><category>Casbaneiro</category><category>Banking Trojan</category><category>Latin America</category><category>Augmented Marauder</category><category>Financial Fraud</category><category>Phishing</category><category>Lateral Movement</category></item><item><title>RoadK1ll WebSocket Implant: New Threat for Stealthy Lateral Movement</title><link>https://runtimerebel.com/blog/roadk1ll-websocket-implant-new-threat-for-stealthy-lateral-movement</link><guid isPermaLink="true">https://runtimerebel.com/blog/roadk1ll-websocket-implant-new-threat-for-stealthy-lateral-movement</guid><description>Analysis of the new RoadK1ll WebSocket implant, detailing its capabilities for lateral movement on compromised networks and offering detection and mitigation strategies.</description><pubDate>Tue, 31 Mar 2026 00:40:12 GMT</pubDate><category>RoadK1ll</category><category>WebSocket</category><category>Lateral Movement</category><category>Post Exploitation</category><category>Implant</category></item><item><title>Warlock Ransomware: BYOVD Techniques and Post-Exploitation Analysis</title><link>https://runtimerebel.com/blog/warlock-ransomware-byovd-techniques-and-post-exploitation-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/warlock-ransomware-byovd-techniques-and-post-exploitation-analysis</guid><description>The Warlock ransomware group has evolved its tactics, utilizing BYOVD techniques and stealthy cross-network activity to bypass EDR and security controls.</description><pubDate>Tue, 17 Mar 2026 16:31:42 GMT</pubDate><category>Warlock Ransomware</category><category>BYOVD</category><category>EDR Evasion</category><category>Lateral Movement</category><category>Post Exploitation</category></item><item><title>Rethinking Password Audits: Protecting Breached &amp; Service Accounts</title><link>https://runtimerebel.com/blog/rethinking-password-audits-protecting-breached-service-accounts</link><guid isPermaLink="true">https://runtimerebel.com/blog/rethinking-password-audits-protecting-breached-service-accounts</guid><description>Traditional password audits often miss critical attack vectors. Learn how compromised credentials, orphaned, and service accounts pose significant threats and how to…</description><pubDate>Mon, 09 Mar 2026 16:32:49 GMT</pubDate><category>Password Audit</category><category>Breached Passwords</category><category>Orphaned Accounts</category><category>Service Accounts</category><category>Identity Management</category><category>Account Security</category><category>Privilege Escalation</category><category>Lateral Movement</category></item><item><title>Attackers Halve Breakout Time to 29 Minutes, CrowdStrike Reports</title><link>https://runtimerebel.com/blog/attackers-halve-breakout-time-to-29-minutes-crowdstrike-reports</link><guid isPermaLink="true">https://runtimerebel.com/blog/attackers-halve-breakout-time-to-29-minutes-crowdstrike-reports</guid><description>CrowdStrike research indicates attackers now achieve lateral movement in just 29 minutes, driven by credential misuse, AI, and blind spots.</description><pubDate>Wed, 25 Feb 2026 04:43:18 GMT</pubDate><category>CrowdStrike</category><category>Breakout Time</category><category>Lateral Movement</category><category>Credential Misuse</category><category>AI in Cyberattacks</category><category>Security Blind Spots</category><category>Adversary Tactics</category></item></channel></rss>